First published: Tue Jul 12 2022(Updated: )
IBM Security Verify Identity Manager 10.0 could allow a privileged user to upload a malicious file by bypassing extension security in an HTTP request. IBM X-Force ID: 224916.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Verify Governance | =10.0 | |
Linux Linux kernel | ||
<=10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-22450.
The severity of CVE-2022-22450 is low with a CVSS score of 3.8.
A privileged user can exploit CVE-2022-22450 by bypassing extension security in an HTTP request to upload a malicious file.
IBM Security Verify Identity Manager 10.0 is affected by CVE-2022-22450.
No, Linux Linux kernel is not vulnerable to CVE-2022-22450.
To fix CVE-2022-22450, IBM recommends applying the necessary patches and updates provided in the official IBM Security Verify Identity Manager documentation.